Vulnerability record · CVE-2022-32174 · published 11 October 2022
CVE-2022-32174: Gogs stored XSS in gogs.js leads to account takeover
Gogs · Gogs
Gogs versions v0.6.5 through v0.12.10 contain a stored cross-site scripting flaw in the client-side code at public/js/gogs.js. Because the injected script persists and executes in other users' sessions, it can be used to take over accounts. The record gives no further detail on the exact injection point or payload.
Description
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS 9.0 stored XSS with account takeover impact and very high EPSS, though it requires an authenticated attacker and victim interaction and is not in KEV.
What it is
Gogs versions v0.6.5 through v0.12.10 contain a stored cross-site scripting flaw in the client-side code at public/js/gogs.js. Because the injected script persists and executes in other users' sessions, it can be used to take over accounts. The record gives no further detail on the exact injection point or payload.
Impact
An attacker who can plant the stored payload can execute script in a victim's browser session and take over that account, including any repository or administrative access the victim holds.
Attack surface
Reachable over the network through the Gogs web interface; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so the attacker needs an authenticated account and the victim must view the affected content.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.58021 (99th percentile) and two references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Gogs past v0.12.10 to a release that fixes the stored XSS in public/js/gogs.js.
- If immediate upgrade is not possible, restrict who can create or edit the content that carries the stored payload and review existing stored content for injected scripts.
- Deploy a Content-Security-Policy that blocks inline and untrusted script execution in the Gogs web UI.
- Enable HttpOnly and Secure flags on session cookies to limit session theft if script does execute.
- Audit accounts for unexpected session or credential changes that could indicate prior exploitation.
Detection
- Search web and proxy logs for requests to Gogs pages containing script tags or encoded script payloads in user-controlled fields.
- Monitor for anomalous authenticated actions such as email, password or SSH key changes shortly after a user views stored content.
- Review stored repository, issue, comment and profile content for inline script or event-handler attributes.
- Alert on Gogs sessions originating from new user agents or IP addresses inconsistent with the account's normal activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/gogs/gogs/blob/v0.12.10/public/js/gogs.js#L263 | ExploitThird Party Advisory |
| https://www.mend.io/vulnerability-database/CVE-2022-32174 | ExploitThird Party Advisory |
| https://github.com/gogs/gogs/blob/v0.12.10/public/js/gogs.js#L263 | ExploitThird Party Advisory |
| https://www.mend.io/vulnerability-database/CVE-2022-32174 | ExploitThird Party Advisory |
Track CVE-2022-32174 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-32174), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.